Junglewise Threat Intelligence

CVE-2026-20786: Intel NPU Driver out-of-bounds read denial of service

CVE-2026-20786 · Severity: info · CVSS 6.9 · Published 2026-08-11

Technologies: Intel NPU Driver for Windows, Intel NPU Driver for Linux. Vendors: Intel.

Executive brief

Intel's NPU (Neural Processing Unit) Driver is used to enable AI acceleration on systems with Intel processors. An authenticated local user can trigger an out-of-bounds memory read that crashes the system or degrades performance, resulting in denial of service. This affects both Linux and Windows versions of the driver.

Technical details

This vulnerability is an out-of-bounds read in the Intel NPU Driver affecting Ring 3 user applications. An authenticated local attacker with low complexity can trigger this memory access violation without special knowledge or user interaction, potentially via improper buffer management or bounds checking. The attack vector is local, requiring prior authentication but not elevated privileges. The vulnerability impacts system availability (high severity) and has a minor integrity impact. A patch is available for both Linux (version 1.32.0 or later) and Windows (version 32.0.100.4723 or later).

Affected products

  • Intel NPU Driver for Linux before 1.32.0
  • Intel NPU Driver for Windows before 32.0.100.4723

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Patches available: Linux 1.32.0 and Windows 32.0.100.4723

References

Related threats